CVE-2024-5754
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-5754 is a vulnerability discovered in the Zephyr Bluetooth host related to the encryption procedure. The vulnerability was disclosed on September 13, 2024, affecting Zephyr versions 3.6 and earlier. The issue exists in the way the host code handles encryption procedures, where it incorrectly trusts and uses encryption change event parameters (Zephyr Advisory).

Technical details

The vulnerability occurs when a malicious Bluetooth Peripheral imitates a Negative Reply with a REJECTIND or REJECTEXTIND using success error codes. The host code incorrectly trusts evt->errorcode rather than evt->encrypt in many cases, leading to a broad assumption throughout the host that the ACL is encrypted despite the encryption being rejected by the peripheral. This affects multiple protocol layers including l2cap, att, smp, and application layers, particularly impacting cases like isochronous channels where an audio stream may be established on a supposedly encrypted link (Zephyr Advisory).

Impact

The vulnerability has been assigned a High severity rating with a CVSS score of 8.2. It primarily affects data confidentiality with high impact and integrity with low impact, while having no direct impact on availability. The vulnerability can be exploited from an adjacent network location without requiring privileges or user interaction (Zephyr Advisory).

Mitigation and workarounds

A workaround has been proposed to translate the status field of the encryption change event to 'UNSPECIFIED' if the procedure was rejected and the link is not encrypted. This can be implemented either in the controller or in the host. Patches have been developed for multiple versions: main (#73945), v3.6 (#74124), v3.5 (#74123), and v2.7 (#74122) (Zephyr Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management